The repository includes tests, a usable README, a small dependency set, and no install-time scripts. The license file says MIT despite a proprietary manifest declaration, and the project has no security scanning or security policy.
58%
Total Score
75
100
75
83
The artifact contains an MIT license file and the repository also has a license file, so the release is licensed. However, the manifest declares proprietary while the detected license is MIT, creating an avoidable licensing ambiguity.
The latest release was published nearly five years ago, with no releases in the last 12 months. This is strong evidence of an aging project and lowers confidence in ongoing compatibility maintenance.
The repository recorded no commits and had no active maintainers during the last three months, consistent with the long release gap. The repository is not archived, but there is no recent activity to offset the maintenance concern.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters more for a network-facing HTTP transport than it would for a purely internal utility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^5.0 | — | — |
3slab/vdm-library-bundle Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.